Sophia
Hart

WaterPlum Cyber Actor Targets Developers via Fake Interviews

Sophia Hart

Sep 21, 2026

5 min read

waterplum cyber actor

TL; DR

  • WaterPlum actors pose as recruiters and use fake technical interviews to trick developers into running malicious code.
  • The group has infected over 30,000 devices in 100-plus countries and compromised 7,000-plus crypto wallets, transferring roughly $10.71 million to North Korea.
  • Malicious npm packages and VS Code projects deliver BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle malware.
  • Successful infections enable credential theft, wallet drains, and lateral movement into employer and client networks.

A joint advisory from agencies in Japan, the United States, Australia, and Germany warns about a North Korean threat group. Investigators call it the WaterPlum cyber actor group, also known as Contagious Interview.

The advisory says WaterPlum actors pose as employers to target software developers and IT professionals. They often impersonate AI, cryptocurrency, and NFT companies to build trust with victims.

The campaign has already infected more than 30,000 devices across over 100 countries. Attackers have stolen funds or credentials from over 7,000 cryptocurrency wallets.

How the fake interview attack works

WaterPlum actors contact targets through job boards, gig platforms, freelance marketplaces, and social media. They pose as hiring managers for AI, blockchain, or NFT startups.

During the interview process, they ask candidates to complete a coding task or fix a bug. The task requires downloading files from a code repository or npm package.

Those files carry hidden malware. Once a victim runs them, the attackers gain a foothold on the device.

Malware capabilities observed in this campaign include:

  • Backdoor access and remote command execution
  • Persistence mechanisms that survive reboots
  • Credential harvesting from browsers and saved sessions
  • Clipboard monitoring and keystroke logging
  • Screenshot capture and file exfiltration
  • Cryptocurrency wallet targeting, including private keys and seed phrases

The malware families behind the campaign

The advisory names five distinct npm-delivered malware families tied to this campaign. Each plays a different role in the intrusion chain.

Malware Type Primary Function
BeaverTail JavaScript loader Initial infection via npm packages
InvisibleFerret Python backdoor Persistent remote access
OtterCookie JavaScript RAT/infostealer Data and credential theft
OtterCandy Combined RAT Combines remote access and infostealer capabilities into a single payload
StoatWaffle Modular Node.js malware Loader, credential harvesting, and lateral pivoting via VS Code

StoatWaffle stands out for its delivery method. It hides inside blockchain-themed VS Code projects using a hidden .vscode/tasks.json file. The file triggers automatic code execution the moment a developer opens the folder and accepts VS Code’s Workspace Trust prompt. Most developers accept that prompt reflexively without reviewing the task configuration first.

Why this reaches beyond the individual developer

A compromised developer laptop rarely stays a personal problem. Attackers can pivot from a single infected machine into employer and client systems.

The advisory notes that successful infections support espionage and intellectual property theft. Attackers can also move laterally into corporate environments through stolen access.

Data at risk extends well beyond crypto wallets:

  • Browser-stored authentication credentials
  • Repository access tokens and source code
  • Corporate VPN or SSO session data
  • Personal ID documents used for impersonation
cybersecurity kit

Cybersecurity kit

Download this cybersecurity kit for blueprints, frameworks, checklists, policy templates, and UEM guidance for enterprises.

DOWNLOAD

Strengthening developer endpoint and identity security

Three Hexnode products address different parts of this attack chain: the compromised device, the malicious process, and the access it leads to.

Hexnode UEM – endpoint compliance

Enforces baseline compliance across every platform it supports: Windows, macOS, Linux, iOS/iPadOS, Android, ChromeOS, and visionOS. For developer endpoints specifically, this covers the desktop platforms teams actually code on: Windows, macOS, and Linux.

  • Flags devices running outdated OS versions as non-compliant, which can then block access to corporate resources through Conditional Access.
  • Restricts unauthorized app installations

Hexnode XDR – behavioral detection

Investigates suspicious activity on managed Windows and macOS endpoints.

  • Flags unexpected process behavior tied to a compromised workflow
  • Supports kill, quarantine, and isolation actions for affected endpoints
  • Marks a developer workstation as non-compliant the moment XDR detects malware, triggering Hexnode IdP to revoke app access automatically
  • Complements vendor-specific remediation rather than replacing it

Hexnode IdP – access control

Ties user identity to real-time device posture via Hexnode’s Device Trust Engine before granting access.

  • Enforces conditional access based on device compliance, not just credentials
  • Applies role-based access so contractors get only what their role needs
  • Requires step-up MFA for high-risk actions.
  • Automates offboarding through SCIM when a contract ends

Book a free demo and explore Hexnode today!

FAQs

WaterPlum builds a multi-week relationship through fake recruiting before delivering malware. This lowers a victim’s guard compared to a single phishing email.

Detection varies by variant and update cycle, so antivirus alone isn’t reliable protection. Never run an interview coding test directly on your host machine. Use an isolated container, virtual machine, or sandbox instead, and only connect it to test data, not real credentials or wallets.

Disconnect the device from the network immediately. Assume credentials and wallet data may already be exposed and rotate them from a separate, clean device.

Conclusion

Fake job interviews have become a credible enterprise intrusion path, not just a personal risk for job seekers. Organizations that outsource development work or hire contractors should treat hiring workflows as part of their attack surface.

Security teams should pair developer endpoint hardening with strict controls on code execution during technical assessments. Contractor and freelancer access deserves the same scrutiny as full-time employee access.

Share

Sophia Hart

A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions—without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable—politely.